CVE-2026-94274
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 30, 2026
Vendor
unknown
Description
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.